CVE-2018-16629

Publication date

2018-12-04 16:00:00

Family

mitre

State

PUBLISHED

Description

panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.